atlas
30a2a2e9de
feat( #2641 ): sudoless hivectl via a hive-admin group on the host socket
...
The host admin socket `/run/hyperhive/host.sock` was `0660 root:root` (no
SocketGroup), so hivectl needed sudo. Group-own it by a new `hive-admin`
group and add a `services.hyperhive.c0re.adminUsers` allowlist: listed users
join `hive-admin` and drive hivectl without root.
- `SocketGroup = "hive-admin"`, `SocketMode = "0660"` on the hive-c0re.socket
unit.
- `/run/hyperhive` -> `0751` (traverse-only, no listing) so the group can reach
the socket path; the socket's own `0660 hive-admin` mode gates the
connection, and the per-agent subdirs keep their own restrictive perms.
- Empty `adminUsers` (the default) leaves `hive-admin` memberless -> root-only,
as before.
The admin socket is full hive control (spawn/kill/destroy/deploy), so
`adminUsers` is an explicit, opt-in trust grant. Documented in
docs/boundary.md (host admin socket access) + docs/tools/hivectl.md.
2026-07-22 22:50:27 +02:00
..
tools
feat( #2641 ): sudoless hivectl via a hive-admin group on the host socket
2026-07-22 22:50:27 +02:00
turn-loop
refactor: nix/host-modules + nix/agent-modules layout, update doc paths
2026-07-13 22:05:49 +02:00
web-ui
refactor( #2416 ): remove the non-pr config-change flow (request_apply_commit / applycommit)
2026-07-15 21:03:52 +02:00
agent-hierarchy.md
refactor( #2352 ): extract standalone hivectl crate, hive-c0re daemon-only
2026-07-15 22:36:13 +02:00
approvals.md
docs( #2502 ): meta flake input is the forge config repo, deploy overrides to local applied
2026-07-17 01:48:27 +02:00
boundary.md
feat( #2641 ): sudoless hivectl via a hive-admin group on the host socket
2026-07-22 22:50:27 +02:00
ci.md
docs( #2415 ): update docs/ci.md for c0re-owned runner registration
2026-07-16 15:30:34 +02:00
conventions.md
docs( #2552 ): never add #[allow(clippy::...)] — fix lints instead
2026-07-20 19:38:56 +02:00
coordinator.md
restart preserves wanted intent instead of forcing all agents up ( #2540 )
2026-07-17 01:46:12 +02:00
forge.md
fix( #2593 ): mark forge notifications read on broker-delivery
2026-07-19 18:41:51 +02:00
gateway.md
route gateway htpasswd management through a daemon wire command ( #2504 )
2026-07-15 23:23:47 +02:00
github.md
fix( #1970 ): bake token path into gh/git wrappers — env var didn't reach claude's bash-tool context
2026-07-11 14:12:25 +02:00
gotchas.md
docs: reflect the new nix layout and removed options
2026-07-13 22:23:20 +02:00
knowledge.md
docs(security): ci netns, knowledge .git tmpfs, matrix id/secret split
2026-07-10 19:17:17 +02:00
matrix.md
refactor: nix/host-modules + nix/agent-modules layout, update doc paths
2026-07-13 22:05:49 +02:00
network.md
docs( #1977 ): drop exposeHostPorts proxy history from network.md
2026-07-17 01:08:42 +02:00
observability.md
feat( #2007 ): export per-agent container cpu/mem/disk via otel
2026-07-15 22:51:31 +02:00
persistence.md
docs( #2628 ): update bash tool descriptions, docs, and system prompt for the todo model (trim impl details for agent)
2026-07-22 17:34:12 +02:00
security.md
refactor: nix/host-modules + nix/agent-modules layout, update doc paths
2026-07-13 22:05:49 +02:00
setup.md
refactor( #2416 ): remove the non-pr config-change flow (request_apply_commit / applycommit)
2026-07-15 21:03:52 +02:00
swarm.md
feat( #1997 ): add prettier markdown formatter to treefmt
2026-07-02 23:33:11 +02:00
terminal-rendering.md
refactor( #2416 ): remove the non-pr config-change flow (request_apply_commit / applycommit)
2026-07-15 21:03:52 +02:00
turn-loop.md
refactor( #2112 ): remove the dead stdio transport from hive-agent-mcp
2026-07-11 00:55:41 +02:00
web-ui.md
feat: rename matrix-accounts page to credentials, add github PAT tab
2026-07-11 12:40:13 +02:00